msiql.exe

The application msiql.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘msiql’. While running, it connects to the Internet address customer.sharktech.net on port 80 using the HTTP protocol.
Version:
1.0.1.30

MD5:
8c7c02bcb730346d443da96d4a0f44bc

SHA-1:
caded6145136ffbe7f82aa123c6ea3e4822bb33b

SHA-256:
d5591e8afd21825782f6683a3dbc5f813d8e27ab435090d8ce296fb9e9ebfabf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/6/2024 1:32:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TopTools (M)
17.1.30.18

File size:
2 MB (2,099,200 bytes)

Product version:
1.0.1.30

Copyright:
Copyright (C) 2015

Original file name:
jkajskdfj

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\windows\temp\00005978\msiql.exe

File PE Metadata
Compilation timestamp:
11/27/2004 4:21:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x21ACCF

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 4F, 02, 00, 00, 4B, 66, 4B, 75, FC, 4A, 4F, 19, CF, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, EB, 03, 80, CF, C3, 73, E6, F6, D2, 8D, 3B, 81, D9, E6, 13, 00, 00, 71, DA, 20, C6, 4E, 90, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, C3, 87, D6, 4A, 42, 68, 99, 51, C7, CA, EB, 40, 3C, BB, 4D, 52, 6A, 15, 6A, FF, E8, 10, 02, 00, 00, 83, C4, 04, 5B, 5F, FF, D7, E8, CD, 01, 00, 00, 81, BD, 32, FF, FF, FF, B6, 01, 00, 00, 0F, 8E...
 
[+]

Entropy:
6.4372

Code size:
1.6 MB (1,626,112 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
msiql

Command:
C:\windows\temp\00005978\msiql.exe \running


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to customer.sharktech.net  (104.160.178.242:80)

TCP (HTTP):
Connects to host-197.199.253.140.etisalat.com.eg  (197.199.253.140:80)

Remove msiql.exe - Powered by Reason Core Security